Fake Claude desktop app in Bing ads delivers SectopRAT malware through Anthropic-hosted page

Attackers used sponsored Bing search results and a fake Claude desktop app to infect organizations with remote-access and info-stealing malware. Huntress says the campaign, dubbed FakeAgent, compromised at least 29 organizations on July 21-22, 2026. The lure used a malicious Claude Artifact hosted on a legitimate Claude.ai domain, then delivered a fake ClaudeDesktop.exe that sideloaded a malicious libcef.dll to install SectopRAT, also known as ArechClient2, and set persistence via a scheduled task created by DockerDesktop.exe.
Why it matters: People searching for trusted software can be infected even when the lure appears on a real vendor domain. Organizations should block or scrutinize sponsored search results, hunt for SectopRAT indicators, and remind users to verify downloads through known-good vendor paths.

Sources

Fake Claude app promoted by Bing ads pushes SectopRAT malware
Bill Toulas 2026.07.23 100% relevant
This article establishes a distinct malvertising and malware-delivery campaign centered on Bing ads, a malicious Claude Artifact on Claude.ai, and SectopRAT infections at at least 29 organizations.
← Back to all stories